Enterprise Cisco Lab & Infrastructure Engineering

Scope: Multi-VLAN Architecture, OSPF Dynamic Routing, Trunking & Infrastructure Security

Project Overview

Designed, configured, and validated a multi-tier enterprise network topology utilizing Cisco routers and Layer 2/Layer 3 switches. The lab environment simulates a scalable branch-to-core infrastructure featuring segmented departmental VLANs, resilient inter-VLAN routing, dynamic OSPF routing, and hardened network edge security.

Cisco Lab Topology & Source Architecture

Enterprise Cisco Multi-VLAN and OSPF Network Topology Diagram
Core / Distribution Architecture

Cisco Packet Tracer Multi-VLAN & OSPF Lab Model

Verified Convergence

Core Network Architecture & Implementation

VLAN Segmentation & Trunking

Configured departmental VLANs (Management, Data, VoIP, and Guest) on Layer 2 switches. Implemented 802.1Q trunking with custom Native VLAN mapping and active DTP disabling for security.

Inter-VLAN Routing & L3 Switching

Deployed Router-on-a-Stick (ROAS) sub-interfaces on Cisco routers and configured Switched Virtual Interfaces (SVIs) on Layer 3 switches for high-throughput inter-departmental packet routing.

OSPF Dynamic Routing

Implemented Single-Area OSPF (Area 0) across core routers. Configured passive interfaces to prevent unauthorized routing updates on client-facing subnets and calibrated link metrics.

Security Hardening & NAT

Configured Port Security (Sticky MAC limits), SSH access (RSA 2048-bit keys), Access Control Lists (Extended ACLs), and Dynamic NAT/PAT for secure edge internet gateway connectivity.

Infrastructure Operations & Verification Protocols

Dynamic Adjacency Validation

Monitored link-state database updates and verified peer neighbor states across core nodes to maintain route convergence and low-latency failover resilience.

Traffic Segmentation Auditing

Audited 802.1Q encapsulation frames and trunk connection health to ensure strict logical isolation across administrative and operational subnets.

Edge Access Safeguards

Enforced encrypted remote access protocols, restricted management console permissions, and applied interface-level MAC security controls.

Key Outcomes & Technical Highlights

100% VLAN Isolation
OSPF Area 0 Convergence
PAT / NAT Edge Gateway
SSH v2 Hardened Remote Access